A fake migration site designed to harvest your wallet recovery phrase was posted directly from COLDCARD's official X account, and the company has no idea how it got there.

COLDCARD, one of the most trusted names in Bitcoin hardware wallets, confirmed the breach after a security researcher tore apart the phishing site and found exactly what it was built to do: collect seed phrases. The link appeared legitimate because it came from COLDCARD's own verified account. No warning label. No obvious red flag. Just a post that looked like any other official announcement.

The company has since pulled the post and issued a public warning, but the damage window was real. Anyone who visited that link and entered their recovery phrase during that period may have already handed over full access to their wallet.

Here is the part that makes this worse. COLDCARD says it found no matching login record for whoever posted the phishing content. That means either the account was compromised through a method that left no trace in X's own access logs, a third-party app connected to the account was exploited, or something inside the platform itself allowed the post to appear. None of those explanations are comforting.

This is not a story about a careless user clicking a bad link. This is a compromised communication channel used by a company that sells products specifically marketed to people who take security seriously. COLDCARD's entire value proposition is that it keeps your Bitcoin safe from remote attacks. The attack did not touch the hardware. It targeted the humans trusting the brand.

What you need to do right now:

If you saw any post from COLDCARD's X account in the past 48 to 72 hours promoting a migration, update, or new platform, do not interact with any links from that window. If you visited a site and entered your seed phrase anywhere, treat that wallet as fully compromised. Move your funds to a fresh wallet with a new seed phrase immediately.

More broadly, this is a reminder that verified social media accounts are not a security guarantee. They are a target. Hardware wallet companies, exchanges, and protocol teams all live in the same vulnerable X ecosystem where SIM swaps, OAuth exploits, and session hijacking are documented attack vectors.

Watch for COLDCARD's follow-up investigation. If a third-party app or connected service was the entry point, every other hardware wallet brand with a social presence faces the same exposure. The real story here is not just one phishing post. It is the question of whether any official crypto account on X can actually be trusted as a communication layer for security-critical information.

Right now, assume it cannot.